Описание
Kubernetes CSI Sidecar Containers Can Allow Unauthorized Data Access
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2019-11255
- https://github.com/kubernetes/kubernetes/issues/85233
- https://access.redhat.com/errata/RHSA-2019:4054
- https://access.redhat.com/errata/RHSA-2019:4096
- https://access.redhat.com/errata/RHSA-2019:4099
- https://access.redhat.com/errata/RHSA-2019:4225
- https://groups.google.com/forum/#!topic/kubernetes-security-announce/aXiYN0q4uIw
- https://security.netapp.com/advisory/ntap-20200810-0003
Пакеты
github.com/kubernetes-csi/external-provisioner
< 0.4.3
0.4.3
github.com/kubernetes-csi/external-provisioner
>= 1.0.0, < 1.0.2
1.0.2
github.com/kubernetes-csi/external-provisioner
= 1.1
Отсутствует
github.com/kubernetes-csi/external-provisioner
>= 1.2.0, < 1.2.2
1.2.2
github.com/kubernetes-csi/external-provisioner
>= 1.3.0, < 1.3.1
1.3.1
github.com/kubernetes-csi/external-snapshotter/v6
>= 1.0.0, < 1.0.2
1.0.2
github.com/kubernetes-csi/external-snapshotter/v6
= 1.1
Отсутствует
github.com/kubernetes-csi/external-snapshotter/v6
>= 1.2.0, < 1.2.2
1.2.2
github.com/kubernetes-csi/external-resizer
= 0.1
Отсутствует
github.com/kubernetes-csi/external-resizer
= 0.2
Отсутствует
Связанные уязвимости
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Improper input validation in Kubernetes CSI sidecar containers for external-provisioner (<v0.4.3, <v1.0.2, v1.1, <v1.2.2, <v1.3.1), external-snapshotter (<v0.4.2, <v1.0.2, v1.1, <1.2.2), and external-resizer (v0.1, v0.2) could result in unauthorized PersistentVolume data access or volume mutation during snapshot, restore from snapshot, cloning and resizing operations.
Уязвимость программного средства управления кластерами виртуальных машин Kubernetes, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю оказать воздействие на конфиденциальность и целостность защищаемой информации